Developers
Connect Claude, ChatGPT or another MCP client to your BMC account with OAuth, without copying tokens, and work with your data in natural language.
MCP (Model Context Protocol) is the standard an AI assistant uses to call external tools. The BMC MCP server exposes 55 tools on top of the API: look up invoices and contacts, prepare a signature envelope, see the tax position. The assistant only sees and does what the role of the connection allows, and BMC checks the permission on every call.
The full list, with the permission and access type of each tool, is in MCP tools. If you are not technical and want the steps for your assistant (ChatGPT, Claude, Gemini, Cursor, n8n…), go to Connect your AI.
https://app.bm.consulting/mcp The server uses the Streamable HTTP transport and OAuth 2.1 with PKCE. It also accepts a bmc_live_… token as an Authorization: Bearer header.
https://app.bm.consulting/mcp. If the dialog asks for the OAuth client, choose Register automatically.On Claude Team and Enterprise an Owner adds the connector under Organization settings › Connectors and each member connects with their own account from Customize › Connectors. Claude Free allows one custom connector. Connectors on your account also appear in Claude Desktop.
claude mcp add --transport http bmc https://app.bm.consulting/mcp Then run /mcp inside Claude Code, choose bmc and click Authenticate.
Point the client at https://app.bm.consulting/mcp. It must support:
plain method is rejected).token_endpoint_auth_method: "none").https://… (exact match) or loopback (http://127.0.0.1:<port>/…, http://[::1]:<port>/… or http://localhost:<port>/…, any port).resource=https://app.bm.consulting/mcp parameter (RFC 8707).
The client discovers the rest on its own: the server answers 401 with the address of its metadata
(/.well-known/oauth-protected-resource/mcp) and from there the client reaches the authorisation server
(/.well-known/oauth-authorization-server).
The access token lasts 1 hour and the refresh token 30 days, and the client renews them on its own. Neither outlives the expiry of the connection.
| Role | Read | Modify data | Critical actions |
|---|---|---|---|
| Analyst | Yes | No | No |
| Operator | Yes | Yes, except credentials and webhooks | No |
| Custom | What you choose | What you choose | Only if you grant them |
A tool only appears in the client if the role covers its permission. With the Analyst role you will see at most the 27 read tools, never the write ones.
Each connection appears under Developers › API & MCP › Credentials as a credential of type MCP, named after the client that created it.
A bmc_live_… token from Credentials also works as an
Authorization: Bearer header, with the same tool filtering: the client only sees the tools its
permissions cover. It is the route for clients without OAuth, for your own agents and for working across several
companies or groups at once.
Examples for each client in Connect your AI.
| Symptom | Likely cause | What to do |
|---|---|---|
| The connection is established but the client shows 0 tools. | The role or the account does not give permissions that open any tool. | Check the role under Credentials. If it is Custom, add permissions; if the account has no data in those areas, there will be no tools. |
| OAuth error when authorising, or the account is not in the list. | API access is not enabled on the account, or you are not an owner or administrator. | Ask BMC to enable access (plataforma@bm.consulting) or ask an account administrator to do it. |
| The client asks you to authorise again after a while. | The refresh token (30 days) or the expiry you set on the connection has run out. | Connect again and, for fewer interruptions, choose a longer expiry. |
| The client rejects the registration or the redirect. | It does not meet PKCE S256, registration as a public client or the redirect URI rules. | Check the requirements under «Other MCP clients». |
If the problem persists, write to plataforma@bm.consulting with the name of the MCP client and the time of the attempt.